Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Emirhan Kurt

#20462of 56,330
13.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-86505
4.8
2026-09-06
Undefined · Undefined · CVE-2026-19862
🚨 CVE-2026-19862 The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field. 🎖@cveNotify
PT-2026-61532
9.1
2026-06-29
WordPress · Kirki · CVE-2026-13147
**Name of the Vulnerable Software and Affected Versions** Kirki WordPress plugin versions prior to 6.0.12 **Description** An issue exists where the software fails to validate a user-supplied URL before requesting it server-side. This allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF), a technique where the server is coerced into making HTTP requests to arbitrary hosts. **Recommendations** Update Kirki WordPress plugin to version 6.0.12 or later.